VDB

CVE-2021-37532

CVE-2021-37532 PUBLISHED CVSS 4.300000190734863 MEDIUM

SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be restricted to high privileged User.

EPSS 0.24% · 47.7th percentile

Risk Scores

CVSS v3.0
4.300000190734863
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.24%
47.7th percentile

Affected Products

VendorProductVersions
SAP SESAP Business One< 10.0
sapbusiness_one10.0

Timeline

  • Sep 14, 2021 CVE Published
  • Sep 15, 2021 EPSS Score
  • Nov 11, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 8, 2022 EPSS Score
  • Mar 6, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 3, 2022 EPSS Score
  • Jun 29, 2022 EPSS Score
  • Aug 26, 2022 EPSS Score
  • Oct 23, 2022 EPSS Score
  • Dec 19, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›